Problem
polylane auth status treats the existence of a locally unexpired credential as authenticated even when /v1/auth/whoami rejects that credential on the selected API domain or cannot be reached. The command catches every validation error and then unconditionally prints authenticated: true.
This is reproducible with an unexpired production OAuth credential in the single global ~/.polylane/credentials.json while selecting POLYLANE_API_DOMAIN=api.baseberry.cc: the UAT identity request returns 401, but status reports success. That is unsafe for cross-environment validation and automation.
Required behavior
- Remote identity validation against the selected API domain is authoritative.
- A 401 or otherwise invalid credential reports unauthenticated with auth-class exit/error semantics and a useful sign-in hint.
- Network, timeout, malformed-response, and server failures remain distinguishable from invalid credentials; they must not claim either authenticated success or credential invalidity without evidence.
- A successful same-environment validation preserves the current status details.
- Preserve credential storage/precedence, OAuth refresh behavior, API-key and MCP scope enforcement, and installer behavior from coreplanelabs/polylanedotcom#111.
- Documentation must describe OAuth client overrides as environment-bound without inventing non-production client IDs or secrets.
Proof required
Red-first regressions for:
- unexpired credential issued for another environment,
- selected-domain 401,
- network failure/unknown state,
- successful same-environment baseline.
Update the covering living spec/docs in the same PR.
Context
Related but not completion of this defect: #34 and #36 cover runtime OAuth client overrides; coreplanelabs/nominal#1165 records the separate UAT client-provisioning gap. This issue must introduce no OAuth client provisioning, credentials, configuration changes, login retries, or deployment side effects.
Problem
polylane auth statustreats the existence of a locally unexpired credential as authenticated even when/v1/auth/whoamirejects that credential on the selected API domain or cannot be reached. The command catches every validation error and then unconditionally printsauthenticated: true.This is reproducible with an unexpired production OAuth credential in the single global
~/.polylane/credentials.jsonwhile selectingPOLYLANE_API_DOMAIN=api.baseberry.cc: the UAT identity request returns 401, but status reports success. That is unsafe for cross-environment validation and automation.Required behavior
Proof required
Red-first regressions for:
Update the covering living spec/docs in the same PR.
Context
Related but not completion of this defect: #34 and #36 cover runtime OAuth client overrides; coreplanelabs/nominal#1165 records the separate UAT client-provisioning gap. This issue must introduce no OAuth client provisioning, credentials, configuration changes, login retries, or deployment side effects.